Fallos del tipo CWE-306

2619 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-4428MEDIUMSensetive Data Exposure in Menulux Managment PortalEPSS 0.5%CVE-2026-72871HIGHDokploy: Unauthenticated Git Provider Injection via GitHub OAuth CallbackEPSS 0.5%CVE-2026-8446HIGHLangflow is affected by security vulnerabilities in Model Context Protocol featuresEPSS 0.5%CVE-2025-26360MEDIUMA CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to versioEPSS 0.5%CVE-2025-2407CRITICALMissing Authentication & Authorization in Web-API allows adversary unrestricted accessEPSS 0.5%CVE-2026-59160HIGHYeger: Unauthenticated Network-Exposed Turborepo Task Execution via /api/runEPSS 0.5%CVE-2026-61094HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.5%CVE-2026-61285HIGHVulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported veEPSS 0.5%CVE-2026-7844MEDIUMchatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authenticationEPSS 0.5%CVE-2026-60883HIGHVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported versions that are afEPSS 0.5%CVE-2026-60925HIGHVulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.5%CVE-2026-55528HIGHpraisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)EPSS 0.5%CVE-2026-46922HIGHVulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.5%CVE-2026-60918HIGHVulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions thatEPSS 0.5%CVE-2026-34279CRITICALVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported EPSS 0.5%CVE-2026-60335HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.5%CVE-2026-65105HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service wEPSS 0.5%CVE-2026-60153HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected EPSS 0.5%CVE-2026-60396HIGHVulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23EPSS 0.5%CVE-2026-55533HIGHPraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secretEPSS 0.5%